Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Certificate issue #83

Open
IzzySoft opened this issue Feb 8, 2024 · 7 comments
Open

Certificate issue #83

IzzySoft opened this issue Feb 8, 2024 · 7 comments

Comments

@IzzySoft
Copy link

IzzySoft commented Feb 8, 2024

A scan (see here for details and background) just revealed the APKs at your releases are signed using a debug key. As that has security implications, may I ask you to please switch to a proper release key, and provide the corresponding APK signed with it? Thanks in advance!

@Martinvlba
Copy link
Contributor

Martinvlba commented Feb 16, 2024

Thx for letting know, I'll see when i get some free time and do the necessary edits for signed release builds

@IzzySoft
Copy link
Author

Thanks!

@IzzySoft
Copy link
Author

IzzySoft commented Mar 9, 2024

So did you have a chance, @Martinvlba? I'm now in the final cleanup round; end of this month the last debugkey-signed APKs must be gone. Would be great if yours could be replaced until then – otherwise it will be gone from my repo at least for the time being and we'd need to reestablish the listing later then.

Not meant as pressure, just as orientation. I'll push your app to the end of the list once more for now.

@Martinvlba
Copy link
Contributor

Martinvlba commented Mar 9, 2024

Would it be okay if i include public release key for automated workflow releases?

so fdroid checks wont tag any issues with neoterm apk's

@IzzySoft
Copy link
Author

I'm not entirely sure what you mean by that – partly because I'm no Android dev, and partly because this is not about F-Droid but about your app in my repo.

What is needed here are releases signed by a release key. IIRC, that would require the private key – which most likely should rather not leave your "safe". I know there are some ways with "secret variables" or such – but not ever having used CI, especially not Githubs, I cannot tell, sorry.

@IzzySoft
Copy link
Author

@Martinvlba last call now. End of month, remaining "debug APKs" will be removed from my repo.

@IzzySoft
Copy link
Author

IzzySoft commented Apr 5, 2024

Sorry to say so, but time's up: apps signed by debug keys are removed now. So is NeoTerm, effective with the next sync around 6 pm UTC. Please give me a ping should you have the issue tackled, so we can relist the app. Meanwhile, all the best for you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants